{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-29T16:53:55.940","vulnerabilities":[{"cve":{"id":"CVE-2021-41661","sourceIdentifier":"cve@mitre.org","published":"2022-06-13T23:15:08.213","lastModified":"2024-11-21T06:26:36.150","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell."},{"lang":"es","value":"Church Management System versión 1.0, está afectada por una vulnerabilidad de inyección SQL mediante la creación de un usuario con un archivo PHP como imagen de avatar, que es accesible mediante el directorio /uploads. Esto puede conllevar a una RCE en el servidor web mediante la carga de un webshell PHP"}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:church_management_system_project:church_management_system:1.0:*:*:*:*:*:*:*","matchCriteriaId":"3CB67E92-061F-4891-A71A-E4EBE1D16AA2"}]}]}],"references":[{"url":"https://github.com/janikwehrli1/0dayHunt/blob/main/Church_Managementv1.0_RCE.py","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/janikwehrli1/0dayHunt/blob/main/Church_Managementv1.0_RCE.py","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}